Methods, devices, equipment, and storage media for monitoring port risks
By performing full port scans and status updates on network assets at the host level and using parameters such as the CPE field to identify vulnerabilities, the problem of inaccurate port monitoring when multiple domains are bound to the same IP address is solved, enabling more accurate risk analysis and routine monitoring.
Patent Information
- Application Number
- CN202410750284.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-12
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2044-06-12
AI Technical Summary
Existing network asset port monitoring methods are insufficient to accurately monitor network assets with multiple domains bound to the same IP address, resulting in inaccurate monitoring results.
By pushing relevant data of network assets to the task queue, a full port scan at the host level is performed to obtain port scan data. Based on parameters such as CPE field, basic fingerprint information of web application and HTTP response header, the port status is updated to identify vulnerabilities and change events, and a pending review status is set to confirm risks.
It improves the accuracy of port monitoring, provides more comprehensive risk analysis, and establishes a routine port monitoring operation from the perspective of the external network.
Smart Images

Figure CN118555116B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the technical field of network assets, specifically to a method, apparatus, device, and storage medium for monitoring port risks. Background Technology
[0002] Existing methods for monitoring network assets typically utilize asset attributes to identify vulnerability information based on rule-based matching. For service ports that support login, further weak password attacks are attempted, and the status of the target asset is dynamically updated during routine scans. However, this port monitoring method struggles to accurately monitor the ports of network assets with multiple domains bound to the same IP address. Summary of the Invention
[0003] This disclosure provides a method, apparatus, device, and storage medium for monitoring port risks.
[0004] According to a first aspect of this disclosure, a method for monitoring port risks is provided, comprising:
[0005] The relevant data of the network assets to be monitored on the port is pushed to the task queue of the first database. The relevant data of the network assets includes IP addresses.
[0006] A scan task request is sent to the scanning end. The scan task request is used to instruct the scanning end to perform a full port scan at the host level for the IP addresses in the task queue, so as to obtain the port scan data corresponding to the IP address and return the port scan data corresponding to the IP address.
[0007] Receive port scan data corresponding to the IP address returned by the scanning end;
[0008] Update the status information of the port corresponding to the IP address based on the port scan data.
[0009] In this embodiment of the disclosure, the port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response header.
[0010] In this embodiment of the disclosure, updating the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address includes:
[0011] The vulnerability information was determined based on the CPE field of the port corresponding to the IP address;
[0012] Compare the port scan data and vulnerability information corresponding to the IP address returned by the scanner this time with the port scan data and vulnerability information corresponding to the IP address returned by the scanner last time.
[0013] When a preset change event is detected in the current port scan data compared to the previous port scan data, the status information of the port corresponding to the IP address is updated.
[0014] In this disclosed embodiment, the change event includes at least one of the following: the emergence of a new vulnerability, the emergence of a new port, or a change in the service type.
[0015] In this embodiment of the disclosure, updating the status information of the port corresponding to the IP address includes:
[0016] Set the port corresponding to the IP address to a pending audit status. The pending audit status indicates that the port corresponding to the IP address needs to be confirmed for risk.
[0017] The scanning flag bit of the port scan data corresponding to the IP address is changed. The changed scanning flag bit is used to indicate that the latest port scan data and its vulnerability information have been stored in the second database.
[0018] In this embodiment of the disclosure, the method for monitoring port risks further includes at least one of the following:
[0019] In response to the information display request, the vulnerability information corresponding to the IP address is queried from the second database, and vulnerability distribution data is generated based on the vulnerability information. The vulnerability distribution data is then sent to the preset monitoring device, so that the monitoring device can display the vulnerability distribution data.
[0020] In response to receiving the search keywords input by the user, the system searches for vulnerability information corresponding to each IP address in the second database based on the search keywords and returns the vulnerability information search results.
[0021] According to the second aspect of this disclosure, another method for monitoring port risks is provided, including:
[0022] Receive scan task requests sent by the server;
[0023] Perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request to obtain the port scan data corresponding to the IP addresses;
[0024] Return the port scan data corresponding to the IP address to the server.
[0025] In this embodiment of the disclosure, a full port scan at the host level is performed on the IP addresses in the task queue indicated by the scan task request to obtain the port scan data corresponding to the IP addresses, including:
[0026] Perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request to obtain the CPE field of the port corresponding to the IP address;
[0027] When it is determined that the protocol of the service on the port corresponding to the IP address is HTTP, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers are obtained.
[0028] According to a third aspect of this disclosure, a port risk monitoring device is provided, which includes a data push module, a request sending module, a scan data receiving module, and a status update module.
[0029] The data push module is used to push relevant data of the network assets to be monitored to the task queue of the first database. The relevant data of the network assets includes IP addresses.
[0030] The request sending module is used to initiate a scan task request to the scanning end. The scan task request is used to instruct the scanning end to perform a full port scan at the host level for the IP addresses in the task queue, so as to obtain the port scan data corresponding to the IP addresses and return the port scan data corresponding to the IP addresses.
[0031] The scan data receiving module is used to receive port scan data corresponding to the IP address returned by the scanning end.
[0032] The status update module is used to update the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address.
[0033] In this embodiment of the disclosure, the port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response header.
[0034] In this embodiment of the disclosure, when the status update module updates the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address, it is specifically used for:
[0035] The vulnerability information was determined based on the CPE field of the port corresponding to the IP address;
[0036] Compare the port scan data and vulnerability information corresponding to the IP address returned by the scanner this time with the port scan data and vulnerability information corresponding to the IP address returned by the scanner last time.
[0037] When a preset change event is detected in the current port scan data compared to the previous port scan data, the status information of the port corresponding to the IP address is updated.
[0038] In this disclosed embodiment, the change event includes at least one of the following: the emergence of a new vulnerability, the emergence of a new port, or a change in the service type.
[0039] In this embodiment of the disclosure, when the status update module is used to update the status information of the port corresponding to the IP address, it is specifically used for:
[0040] Set the port corresponding to the IP address to a pending audit status. The pending audit status indicates that the port corresponding to the IP address needs to be confirmed for risk.
[0041] The scanning flag bit of the port scan data corresponding to the IP address is changed. The changed scanning flag bit is used to indicate that the latest port scan data and its vulnerability information have been stored in the second database.
[0042] In this embodiment of the disclosure, the port risk monitoring device further includes an information application module, which is used to perform at least one of the following:
[0043] In response to the information display request, the vulnerability information corresponding to the IP address is queried from the second database, and vulnerability distribution data is generated based on the vulnerability information. The vulnerability distribution data is then sent to the preset monitoring device, so that the monitoring device can display the vulnerability distribution data.
[0044] In response to receiving the search keywords input by the user, the system searches for vulnerability information corresponding to each IP address in the second database based on the search keywords and returns the vulnerability information search results.
[0045] According to the fourth aspect of this disclosure, another port risk monitoring device is provided, which includes a request receiving module, a port scanning module, and a scan data return module.
[0046] The request receiving module is used to receive scan task requests sent by the server.
[0047] The port scanning module is used to perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request, and obtain the port scan data corresponding to the IP addresses.
[0048] The scan data return module is used to return the port scan data corresponding to the IP address to the server.
[0049] In this embodiment of the disclosure, when the port scanning module performs a full host-level port scan on the IP addresses in the task queue indicated by the scan task request to obtain the port scan data corresponding to the IP addresses, it is specifically used for:
[0050] Perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request to obtain the CPE field of the port corresponding to the IP address;
[0051] When it is determined that the protocol of the service on the port corresponding to the IP address is HTTP, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers are obtained.
[0052] According to a fifth aspect of this disclosure, an electronic device is provided, comprising:
[0053] At least one processor; and a memory communicatively connected to the at least one processor;
[0054] The memory stores instructions that can be executed by at least one processor, which enables the at least one processor to perform the port risk monitoring method provided in the first or second aspect above.
[0055] According to a sixth aspect of this disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause a computer to perform the port risk monitoring method provided in the first or second aspect described above.
[0056] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description.
[0057] The beneficial effects of the technical solution provided in this disclosure are:
[0058] This disclosure pre-associates the IP addresses of ports corresponding to network assets, facilitating in-depth mining of multi-domain network assets bound to the same IP. Simultaneously, it monitors ports based on multi-dimensional parameters such as CPE fields, basic fingerprint information of web applications corresponding to network assets, browser homepage data that has not been redirected, and HTTP response headers, improving the accuracy of monitoring results. It also provides more operational space and analytical guidance for port risk analysis, thereby forming a normalized port monitoring operation from the perspective of the external network. Attached Figure Description
[0059] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:
[0060] Figure 1 A flowchart illustrating a port risk monitoring method provided in an embodiment of this disclosure is shown.
[0061] Figure 2 A flowchart illustrating another port risk monitoring method provided in an embodiment of this disclosure is shown.
[0062] Figure 3A schematic flowchart of a port risk monitoring device provided in an embodiment of this disclosure is shown;
[0063] Figure 4 A flowchart illustrating another port risk monitoring device provided in an embodiment of this disclosure is shown;
[0064] Figure 5 A flowchart illustrating another port risk monitoring device provided in an embodiment of this disclosure is shown;
[0065] Figure 6 A schematic block diagram of an example electronic device that can be used to implement embodiments of the present disclosure is shown. Detailed Implementation
[0066] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0067] Existing methods for monitoring network assets typically utilize asset attributes to identify vulnerability information based on rule-based matching. For service ports that support login, further weak password attacks are attempted, and the status of the target asset is dynamically updated during routine scans. However, this port monitoring method struggles to accurately monitor the ports of network assets with multiple domains bound to the same IP address.
[0068] The port risk monitoring method, apparatus, device, and storage medium provided in this disclosure are intended to solve at least one of the above-mentioned technical problems in the prior art.
[0069] The execution entity of the port risk monitoring method provided in this disclosure can be a computer, a server, or other computing device with data processing capabilities. For example, the aforementioned computer, server, or computing device can be a backend service device in any of the aforementioned application scenarios, such as the backend server of a search engine. This disclosure does not limit the execution entity of the port risk monitoring method.
[0070] In some embodiments, the server can be a single server, or it can be a server cluster consisting of multiple servers. In some embodiments, the server cluster can also be a distributed cluster. This disclosure does not limit the specific implementation of the server.
[0071] Figure 1The diagram illustrates a flowchart of a port risk monitoring method provided in this embodiment. The method is executed by a server, which can act as the master control unit for port risk monitoring. Figure 1 As shown, the method mainly includes the following steps:
[0072] S110: Push the relevant data of the network assets to be monitored on the port to the task queue of the first database.
[0073] Here, network assets refer to Web assets. This embodiment of the disclosure can store the full IP addresses and full domain name information of multiple network assets in a first database for regular updates and maintenance. Before the server initiates a scan task request to the scanning end, it can perform a resolution operation on the full domain names in the first database to obtain a list of mapping relationships between full IP addresses and their corresponding bound domain names. This mapping relationship list includes relevant data of the network assets to be monitored, including IP addresses. Optionally, the first database can be Redis. Redis is an open-source, ANSI C-based, network-enabled, in-memory or persistent log-structured key-value database that provides APIs in multiple languages.
[0074] S120: Initiate a scan task request to the scanning end.
[0075] Here, the scan task request instructs the scanning end to perform a full host-level port scan on the IP addresses in the task queue to obtain the port scan data corresponding to the IP addresses and return the port scan data. The specific process of the scanning end obtaining port scan data will be further introduced in later content and will not be elaborated here.
[0076] S130: Receive port scan data corresponding to the IP address returned by the scanning end.
[0077] In this embodiment, the port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response header. Here, CPE stands for Common Platform Enumeration, a term used specifically for vulnerabilities, referring to a standardized method of naming software applications, operating systems, and hardware. The aforementioned fingerprint serves as a unique identifier for the application. During application development, to improve development efficiency and system stability, mature and stable third-party environments, programs, frameworks, or services are often used. The names or identifiers of these third-party contents are what we refer to as application fingerprints. Based on the flow of network data and combined with a layered approach, common application fingerprints are divided into five categories: network layer fingerprints (e.g., infrastructure fingerprints such as gateways and CDNs); host layer fingerprints (e.g., fingerprints of information systems, software firewalls, and various software providing services on the host); service layer fingerprints (e.g., fingerprints of services such as FTP services); application layer fingerprints (e.g., fingerprints of various website building programs, open-source frameworks, and front-end frameworks); and pre-script layer fingerprints (e.g., pre-script information such as ASP, ASPX, PHP, and JSP).
[0078] S140: Update the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address.
[0079] Here, the port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and HTTP response headers. In step S140, vulnerability information can be determined based on the CPE field of the port corresponding to the IP address. Specifically, after receiving the CPE field, the server can retrieve the corresponding vulnerability information from the first database based on the CPE field. It should be noted that operating system and hardware-level CPEs are automatically ignored. If the corresponding vulnerability information is not found in the first database, the CPE field can be provided to the API of the locally deployed vulnerability database to determine the corresponding vulnerability information from the vulnerability database, and the mapping relationship between the CPE field and the vulnerability information is stored in the first database. After identifying the vulnerability information, the server can compare the port scan data and vulnerability information corresponding to the IP address returned by the scanner this time with the port scan data and vulnerability information corresponding to the IP address returned by the scanner in the previous scan. Specifically, it can compare the CPE field of the port corresponding to the IP address this time, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers with the CPE field of the port corresponding to the IP address this time, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers to determine whether the port scan data this time has undergone a preset change event compared to the port scan data last time. The change event includes at least one of the following: the appearance of a new vulnerability, the appearance of a new port, or a change in service type. When the server determines that the port scan data this time has undergone a preset change event compared to the port scan data last time, it updates the status information of the port corresponding to the IP address.
[0080] In this embodiment of the disclosure, when the server updates the status information of the port corresponding to the IP address, it can set the port corresponding to the IP address to a pending audit status. Here, the pending audit status indicates that the port corresponding to the IP address needs to be confirmed as having a risk. After security personnel or operations and maintenance personnel reconfirm the risk status of the port and take immediate action, the port can be changed from the pending audit status to the normal status.
[0081] In this embodiment of the disclosure, when the server updates the status information of the port corresponding to the IP address, it changes the scanning flag bit of the port scanning data corresponding to the IP address. The changed scanning flag bit is used to indicate that the latest port scanning data and its vulnerability information have been stored in the second database. Here, the second database supports search engine search. For example, relevant information can be searched in the second database based on Elastic Search.
[0082] In this embodiment of the disclosure, the server can respond to an information display request by querying vulnerability information corresponding to an IP address from a second database, generating vulnerability distribution data based on the vulnerability information, and sending the vulnerability distribution data to a preset monitoring device, so that the monitoring device can display the vulnerability distribution data.
[0083] In this embodiment, the server can respond to receiving search keywords input by the user, search for vulnerability information corresponding to each IP address in the second database based on the search keywords, and return the vulnerability information search results. Specifically, the server can implement fuzzy search capabilities based on Elastic Search, allowing users to obtain relevant information from the second database by searching keywords. Specifically, it searches for vulnerability information corresponding to each IP address in the second database using Elastic Search and search keywords, and returns the vulnerability information search results. The vulnerability database can be synchronized to NVD. Some vulnerabilities included in domestic databases may not be included in the database. However, domestic vulnerability databases do not maintain CPE information, requiring manual combination of CPEs to query whether all CPEs under the currently collected assets are included. This scenario is also suitable for the emergency phase when a vulnerability is first exposed. Considering that the fingerprint cannot identify the version, the asset list under the product category can be retrieved, and then POC verification can be carried out, which can also narrow down the scope. Here, POC stands for Proof of Concept, which is a popular industry-standard verification test for specific customer applications. Based on the performance requirements and expansion needs of the system proposed by the user, real data is run on the selected server to actually measure the amount of user data to be carried and the running time. The data volume is increased according to the user's future business expansion needs to verify the system and platform's carrying capacity and performance changes.
[0084] The port risk monitoring method provided in this disclosure can pre-associate the IP addresses of ports corresponding to network assets, facilitating in-depth mining of multi-domain network assets bound to the same IP. Simultaneously, it monitors ports based on multi-dimensional parameters such as CPE fields, basic fingerprint information of web applications corresponding to network assets, browser homepage data that has not been redirected, and HTTP response headers, improving the accuracy of monitoring results. It also provides more operational space and analytical guidance for port risk analysis, thereby forming a normalized port monitoring operation from the perspective of the external network.
[0085] Figure 2 The diagram illustrates a flowchart of another port risk monitoring method provided in this embodiment of the present disclosure. The execution entity of this method is a scanning terminal, such as... Figure 2 As shown, this method mainly includes the following steps:
[0086] S210: Receive scan task requests sent by the server.
[0087] The scan task request sent by the server is used to instruct the scanning end to perform a full port scan at the host level for the IP addresses in the task queue in order to obtain the port scan data corresponding to the IP addresses.
[0088] S220: Perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request to obtain the port scan data corresponding to the IP addresses.
[0089] In this embodiment of the disclosure, a full port scan at the host level is performed on the IP address in the task queue indicated by the scan task request to obtain the port scan data corresponding to the IP address. This includes: performing a full port scan at the host level on the IP address in the task queue indicated by the scan task request to obtain the CPE field of the port corresponding to the IP address; and when it is determined that the protocol of the service of the port corresponding to the IP address is HTTP, obtaining the basic fingerprint information of the Web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response header.
[0090] Specifically, after detecting the IP addresses of the network assets to be monitored in the task queue, the scanning client performs the first stage: a full port scan at the host level. This involves performing a full port scan on all IP addresses in the task queue indicated by the scan task request. Here, the server can use the open-source IVRE client to implement the full port scan process. The scanned data is stored in MongoDB. The IVRE client extracts and parses the JSON-formatted scan data, including the CPE field of the port corresponding to the IP address. Once it is determined that the protocol of the service on the port corresponding to the IP address is HTTP, the second stage, network application fingerprinting, begins. This can be done using a headless browser version of Wappalyzer, which disables browser redirection, to obtain the basic fingerprint information of the corresponding web application. Simultaneously, it collects the browser's unredirected homepage data and HTTP response headers. By simulating a real browser, a more complete page can be obtained for web fingerprinting.
[0091] S230: Return the port scan data corresponding to the IP address to the server.
[0092] It is understandable that the port scan data returned by the scanning end to the server includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers.
[0093] Based on the same principle as the port risk monitoring method described above, this disclosure provides a port risk monitoring device. Figure 3 A schematic diagram of a port risk monitoring device provided in an embodiment of this disclosure is shown, such as... Figure 3As shown, the port risk monitoring device 300 includes a data push module 310, a request sending module 320, a scan data receiving module 330, and a status update module 340.
[0094] The data push module 310 is used to push relevant data of the network assets to be monitored on the port to the task queue of the first database. The relevant data of the network assets includes IP addresses.
[0095] The request sending module 320 is used to initiate a scan task request to the scanning end. The scan task request is used to instruct the scanning end to perform a full port scan at the host level for the IP addresses in the task queue, so as to obtain the port scan data corresponding to the IP addresses and return the port scan data corresponding to the IP addresses.
[0096] The scan data receiving module 330 is used to receive port scan data corresponding to the IP address returned by the scanning end.
[0097] The status update module 340 is used to update the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address.
[0098] The port risk monitoring device provided in this disclosure can pre-associate the IP addresses of ports corresponding to network assets, facilitating in-depth mining of multi-domain network assets bound under the same IP. At the same time, it monitors ports based on multi-dimensional parameters such as CPE fields, basic fingerprint information of web applications corresponding to network assets, browser homepage data that has not been redirected, and HTTP response headers, improving the accuracy of monitoring results. It also provides more operational space and analytical guidance for port risk analysis, thereby forming a normalized port monitoring operation from the perspective of the external network.
[0099] In this embodiment of the disclosure, the port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response header.
[0100] In this embodiment of the disclosure, when the status update module 340 updates the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address, it is specifically used for:
[0101] The vulnerability information was determined based on the CPE field of the port corresponding to the IP address;
[0102] Compare the port scan data and vulnerability information corresponding to the IP address returned by the scanner this time with the port scan data and vulnerability information corresponding to the IP address returned by the scanner last time.
[0103] When a preset change event is detected in the current port scan data compared to the previous port scan data, the status information of the port corresponding to the IP address is updated.
[0104] In this disclosed embodiment, the change event includes at least one of the following: the emergence of a new vulnerability, the emergence of a new port, or a change in the service type.
[0105] In this embodiment of the disclosure, when updating the status information of the port corresponding to the IP address, the status update module 340 is specifically used for:
[0106] Set the port corresponding to the IP address to a pending audit status. The pending audit status indicates that the port corresponding to the IP address needs to be confirmed for risk.
[0107] The scanning flag bit of the port scan data corresponding to the IP address is changed. The changed scanning flag bit is used to indicate that the latest port scan data and its vulnerability information have been stored in the second database.
[0108] In this embodiment of the disclosure, Figure 4 A schematic diagram of another port risk monitoring device provided in an embodiment of this disclosure is shown, such as... Figure 4 As shown, the port risk monitoring device 300 also includes an information application module 350, which is used to perform at least one of the following:
[0109] In response to the information display request, the vulnerability information corresponding to the IP address is queried from the second database, and vulnerability distribution data is generated based on the vulnerability information. The vulnerability distribution data is then sent to the preset monitoring device, so that the monitoring device can display the vulnerability distribution data.
[0110] In response to receiving the search keywords input by the user, the system searches for vulnerability information corresponding to each IP address in the second database based on the search keywords and returns the vulnerability information search results.
[0111] It is understood that the modules of the port risk monitoring device 300 in this embodiment have the function of implementing the corresponding steps of the port risk monitoring method described above. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. The modules can be software and / or hardware, and each module can be implemented individually or multiple modules can be integrated. For a detailed description of the functions of each module of the port risk monitoring device 300, please refer to the corresponding description of the port risk monitoring method described above, which will not be repeated here.
[0112] Based on the same principle as the port risk monitoring method described above, this disclosure provides a port risk monitoring device. Figure 5A schematic diagram of another port risk monitoring device provided in this disclosure embodiment is shown, such as... Figure 5 As shown, the port risk monitoring device 500 includes a request receiving module 510, a port scanning module 520, and a scan data return module 530.
[0113] The request receiving module 510 is used to receive scan task requests sent by the server.
[0114] The port scanning module 520 is used to perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request, and obtain the port scan data corresponding to the IP addresses.
[0115] The scan data return module 530 is used to return the port scan data corresponding to the IP address to the server.
[0116] In this embodiment of the disclosure, when the port scanning module 520 performs a full host-level port scan on the IP addresses in the task queue indicated by the scan task request to obtain the port scan data corresponding to the IP addresses, it is specifically used for:
[0117] Perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request to obtain the CPE field of the port corresponding to the IP address;
[0118] When it is determined that the protocol of the service on the port corresponding to the IP address is HTTP, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers are obtained.
[0119] It is understood that the modules of the port risk monitoring device in this embodiment have the function of implementing the corresponding steps of the port risk monitoring method described above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. These modules can be software and / or hardware; each module can be implemented individually or multiple modules can be integrated. For a detailed description of the functions of each module of the port risk monitoring device, please refer to the corresponding description of the port risk monitoring method described above, which will not be repeated here.
[0120] The collection, storage, use, processing, transmission, provision, and disclosure of customer personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0121] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0122] Figure 6A schematic block diagram of an example electronic device that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0123] like Figure 6 As shown, device 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 602 or a computer program loaded from storage unit 608 into random access memory (RAM) 603. RAM 603 may also store various programs and data required for the operation of device 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.
[0124] Multiple components in device 600 are connected to I / O interface 605, including: input unit 606, such as keyboard, mouse, etc.; output unit 607, such as various types of monitors, speakers, etc.; storage unit 608, such as disk, optical disk, etc.; and communication unit 609, such as network card, modem, wireless transceiver, etc. Communication unit 609 allows device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0125] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above, such as port risk monitoring methods. For example, in some embodiments, the port risk monitoring method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed on device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by the computing unit 601, one or more steps of the port risk monitoring method described above may be performed. Alternatively, in other embodiments, the computing unit 601 may be configured to perform port risk monitoring methods by any other suitable means (e.g., by means of firmware).
[0126] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0127] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0128] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0129] To provide interaction with a customer, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the customer (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the customer provides input to the computer. Other types of devices can also be used to provide interaction with the customer; for example, feedback provided to the customer can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the customer can be received in any form (including voice input, speech input, or tactile input).
[0130] The systems and technologies described herein can be implemented in computing systems that include back-end components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include front-end components (e.g., a client computer with a graphical client interface or web browser through which a client can interact with the implementations of the systems and technologies described herein), or any combination of such back-end, middleware, or front-end components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0131] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0132] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0133] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A method for monitoring port risks, comprising: The relevant data of the network assets to be monitored on the port is pushed to the task queue of the first database, wherein the relevant data of the network assets includes IP addresses; A scan task request is initiated to the scanning end, which is used to instruct the scanning end to perform a full port scan at the host level for the IP addresses in the task queue, so as to obtain the port scan data corresponding to the IP address and return the port scan data corresponding to the IP address. Receive port scan data corresponding to the IP address returned by the scanning terminal; Update the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address; The port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers.
2. The port risk monitoring method according to claim 1, characterized in that, The step of updating the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address includes: Based on the CPE field of the port corresponding to the IP address, the vulnerability information is determined; The port scan data and vulnerability information corresponding to the IP address returned by the scanning terminal this time are compared with the port scan data and vulnerability information corresponding to the IP address returned by the scanning terminal last time. When a preset change event is detected in the current port scan data compared to the previous port scan data, the status information of the port corresponding to the IP address is updated.
3. The port risk monitoring method according to claim 2, characterized in that, The change event includes at least one of the following: the emergence of a new vulnerability, the emergence of a new port, or a change in the service type.
4. The port risk monitoring method according to claim 2, characterized in that, Updating the status information of the port corresponding to the IP address includes: Set the port corresponding to the IP address to a pending audit status. The pending audit status is used to indicate that the port corresponding to the IP address needs to be confirmed for risk. The scanning flag bit of the port scan data corresponding to the IP address is changed. The changed scanning flag bit is used to indicate that the latest port scan data and its vulnerability information have been stored in the second database.
5. The port risk monitoring method according to claim 4, characterized in that, Includes at least one of the following: In response to an information display request, the system queries the vulnerability information corresponding to the IP address from the second database, generates vulnerability distribution data based on the vulnerability information, and sends the vulnerability distribution data to a preset monitoring device, so that the monitoring device displays the vulnerability distribution data. In response to receiving a search keyword input by the user, the system searches for vulnerability information corresponding to each IP address in the second database based on the search keyword and returns the vulnerability information search results.
6. A method for monitoring port risks, comprising: Receive scan task requests sent by the server; Perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request to obtain the port scan data corresponding to the IP addresses; Return the port scan data corresponding to the IP address to the server; The port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers.
7. The port risk monitoring method according to claim 6, characterized in that, The step of performing a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request, and obtaining the port scan data corresponding to the IP addresses, includes: Perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request to obtain the CPE field of the port corresponding to the IP address; When it is determined that the protocol of the service on the port corresponding to the IP address is HTTP, the basic fingerprint information of the Web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response header are obtained.
8. A port risk monitoring device, comprising: The data push module is used to push relevant data of the network assets to be monitored to the task queue of the first database, wherein the relevant data of the network assets includes IP addresses; The request sending module is used to initiate a scan task request to the scanning end. The scan task request is used to instruct the scanning end to perform a full port scan at the host level for the IP addresses in the task queue, so as to obtain the port scan data corresponding to the IP address and return the port scan data corresponding to the IP address. The scan data receiving module is used to receive port scan data corresponding to the IP address returned by the scanning terminal; The status update module is used to update the status information of the port corresponding to the IP address based on the port scan data corresponding to the IP address. The port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers.
9. A port risk monitoring device, comprising: The request receiving module is used to receive scan task requests sent by the server. The port scanning module is used to perform a full port scan at the host level on the IP addresses in the task queue indicated by the scan task request, and obtain the port scan data corresponding to the IP addresses; The scan data return module is used to return the port scan data corresponding to the IP address to the server; The port scan data includes the port's CPE field, the basic fingerprint information of the web application corresponding to the network asset, the browser's unredirected homepage data, and the HTTP response headers.
10. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the port risk monitoring method of any one of claims 1-5, or to perform the port risk monitoring method of any one of claims 6-7.
11. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the port risk monitoring method according to any one of claims 1-5, or to execute the port risk monitoring method according to any one of claims 6-7.
Citation Information
Patent Citations
Distributed scanning internal network asset management method, system and device and memory medium
CN107979597A
Industrial asset detection method, equipment and device
CN113240258A